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Monge, Elaine (SCA) 


From: noreply@formstack.com 

Sent: Wednesday, June 21, 2017 6:27 PM 

To: Breaches, Data (SCA) 

Subject: Security Breach Notifications 



Formstack Submission for form Security Breach Notifications 

Submitted at 06/21/17 6:26 PM 


Business Name: •: Jones Day 

Business Address: 250 Vesey Street 

New York, NY 10281 

Company Type: Other 

Your Name: Mauricio Paez 

Title: Partner 

Contact Address: 250 Vesey Street 

New York, NY 10281 

Telephone Number: (212) 326-7889 

Extension: 

Email Address: .7: mpaez@jonesday.com : '.v. 

Relationship to Org: Owner 

Breach Type: Electronic 

Date Breach was Discovered: 06/14/2017 

Number of Massachusetts Residents 4 

Affected: 

Person responsible for data breach.: 3rd Party Provider 

Please give a detailed explanation of The Sabre Hospitality Solutions SynXis Central Reservations system 

how the data breach occurred.: (Hospitality CRS) facilitates the booking of hotel reservations made by 

consumers through hotels, online travel agencies, and similar booking 
services. Following an examination of forensic evidence, Sabre 
notified Lawyers Travel Services, our travel services provider, on or 
about June 6, 2017 that an unauthorized party gained access to 
account credentials that permitted unauthorized access to 
unencrypted payment card information, as well as certain reservation 
information, for a subset of hotel reservations processed through the 
Hospitality CRS. Sabre’s investigation determined that the 
unauthorized party first obtained access to payment card and other 
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reservation information on August 10, 2016. The last access to 
payment card information was on March 9, 2017. 

Please select the type of personal Credit/Debit Card Number = Selection(s) 
information that was included in the 
breached data.: 

The breach occurred at the location of a third party service provider. = 
Selection(s) 

There is a written contract in place with the third-party provider 
requiring protection of personal information. = Selection(s) 

For breaches involving paper: A lock N/A 
or security mechanism was used to 
physically protect the data.: 

Physical access to systems N/A 

containing personal information was 
restricted to authorized personnel 
only.: 

Network configuration of breached N/A 

system: 

For breaches involving electronic Breached data was encrypted. = Selection(s) 

systems, complete the following: Personal information stored on the breached system was password- 

protected and/or restricted by user permissions. = Selection(s) 

All Massachusetts residents affected Yes 
by the breach have been notified of 
the breach.: 

Method(s) used to notify E-mail = Selection(s) 

Massachusetts residents affected by 
the breach (check all that apply):: 

Date notices were first sent to 06/22/2017 

Massachusetts residents 

(MM/DD/YYYY): 

All Massachusetts residents affected Yes 
by the breach have been offered 
complimentary credit monitoring 
services .: 

Law enforcement has been notified Yes 
of this data breach.: 

Please describe how your company Sabre is committed to a global, holistic security program focused on 
responded to the breach. Include protecting its systems. In fact, its level of investment in state of the art 

what changes were made or may be security technology and highly qualified personnel has more than 

made to prevent another similar tripled since 2013. Using a layered security approach, Sabre has 

breach from occurring.: enhanced the security around its access credentials and the 

monitoring of system activity to further detect and prevent 
unauthorized access. Consistent with that approach, Sabre enlists 
best-in-class external resources to reassure you that Sabre addresses 
security with the utmost care and expertise. 


Please check ALL of the boxes that 
apply to your breach.: 
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